Under the California Consumer Privacy Act, you have the right to deletion: you can ask a covered business to erase the personal information it has collected about you, and it generally has 45 calendar days to do it. The right reaches past the company itself to its service providers, contractors, and any third parties that received your data through a sale or share.1California Legislative Information. California Civil Code 1798.105 – Consumers Right to Delete Personal Information It isn’t absolute. The law lists specific reasons a business can keep some or all of your data, and those exceptions are where most disputes start.
Which Businesses Have to Delete Your Data
The CCPA applies to for-profit businesses that collect personal information from California residents and hit at least one of three thresholds: annual gross revenue above roughly $26.6 million (adjusted yearly for inflation), buying or selling the personal information of 100,000 or more consumers or households, or earning 50 percent or more of annual revenue from selling or sharing personal information.2California Privacy Protection Agency. Updated Monetary Thresholds in CCPA A company that falls below all three is not required to honor a deletion request, though some choose to anyway.
The “personal information” a covered business must delete is defined broadly. It includes obvious identifiers like your name, address, email, Social Security number, and IP address, along with purchase history, browsing and search activity, precise geolocation, biometric data, employment and education records, and inferences drawn from any of it. Publicly available information and data that has been properly de-identified or aggregated fall outside the definition and are not subject to deletion.3California Legislative Information. California Civil Code 1798.140 – Definitions
How to Submit a Deletion Request
Every covered business must offer at least two ways to submit a request. A toll-free number, an email address, a web form, or a physical mailing option all qualify. If the business operates only online, an email address alone is enough.4State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA) Most companies post a “Delete My Personal Information” link or spell out the process in their privacy policy. A business cannot force you to create an account just to make the request, but if you already have one, it can require you to submit through that account.5California Legislative Information. California Civil Code 1798.130 – Notice, Disclosure, Correction, and Deletion Requirements
Give the company enough information to identify you. Your name, email, and any account details linked to the data usually suffice, though a business handling more sensitive information may ask for extra verification, such as a code sent to your phone or a reply to a confirmation email. Be specific about what you want deleted. You can ask for everything or for particular categories, like purchase records or browsing history.
You can also authorize someone else to act for you. The business may ask for proof, such as your signed written permission or a power of attorney.4State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)
The Two-Step Confirmation for Online Requests
If you submit online, the regulations require a two-step process: you send the initial request, and then you separately confirm it, typically through a link in a follow-up email or a second prompt in the company’s portal. This safeguard exists to keep accidental clicks and bots from wiping out real accounts. Requests made by phone or mail don’t trigger the second step.
What Happens After You Submit
Once your identity is verified, the business has 45 calendar days to delete the data and tell you what it did. It can extend that window by another 45 days if your request is unusually complex or it’s dealing with a heavy volume, but only if it notifies you of the delay and the reason within the first 45 days.5California Legislative Information. California Civil Code 1798.130 – Notice, Disclosure, Correction, and Deletion Requirements
The final notification has to tell you whether the business complied. If anything was held back under an exception, the notice must identify which exception applies. The company must still delete whatever data falls outside that exception, and it cannot use the retained data for any purpose beyond what the exception permits.6Legal Information Institute (Cornell Law School). California Code of Regulations Title 11 7022 – Requests to Delete Save the confirmation. It’s the clearest evidence you’ll have if the company’s compliance is ever in question.
If a business decides not to act on your request at all, it has to tell you why within the response period and describe any appeal rights.5California Legislative Information. California Civil Code 1798.130 – Notice, Disclosure, Correction, and Deletion Requirements
When a Business Can Legally Refuse
A business can decline to delete data that is reasonably necessary for any of the following:1California Legislative Information. California Civil Code 1798.105 – Consumers Right to Delete Personal Information
- Completing a transaction you’re part of, including an active order, subscription, warranty, or product recall.
- Detecting security incidents or protecting against malicious, deceptive, or illegal activity, and identifying those responsible.
- Debugging to identify and repair errors in existing functionality.
- Exercising the business’s free speech rights or protecting another consumer’s exercise of free speech.
- Complying with the California Electronic Communications Privacy Act, such as preserving records under a valid court order.
- Public-interest scientific, historical, or statistical research, if deletion would seriously impair the work and you originally consented to that use.
- Internal uses reasonably aligned with the relationship you have with the business.
- Complying with other federal or state legal obligations.
“Reasonably necessary” is the operative phrase. A company cannot invoke an exception as a general shield over its whole database. It has to identify which exception applies, explain why, and delete anything that falls outside its scope.6Legal Information Institute (Cornell Law School). California Code of Regulations Title 11 7022 – Requests to Delete
What Deletion Actually Looks Like
When no exception applies, the business must use one of three permitted methods: permanently erase the data from its active systems, de-identify it so it can no longer be linked to any person, or aggregate it into datasets where individual identities are fully obscured. Data sitting on archived or backup systems can wait to be deleted until that backup is restored to active use or next accessed for a commercial purpose.6Legal Information Institute (Cornell Law School). California Code of Regulations Title 11 7022 – Requests to Delete
The obligation extends downstream. The business must direct its service providers and contractors to delete the data, and it must notify every third party to whom it sold or shared your information to do the same, unless doing so would be impossible or involve disproportionate effort.1California Legislative Information. California Civil Code 1798.105 – Consumers Right to Delete Personal Information If the company claims disproportionate effort, the regulations require it to explain the obstacle in enough detail that you can actually understand it. A bare assertion that notifying third parties is too hard does not meet the standard.6Legal Information Institute (Cornell Law School). California Code of Regulations Title 11 7022 – Requests to Delete
After deletion, the business can keep a confidential record that your request was made. That isn’t a loophole. It exists so the company can keep your data from being re-collected or sold and can prove compliance if it’s audited.1California Legislative Information. California Civil Code 1798.105 – Consumers Right to Delete Personal Information
The Business Cannot Retaliate Against You
The CCPA prohibits a business from punishing you for exercising a privacy right. It cannot deny you goods or services, charge you a higher price, provide a lower quality of service, or even suggest any of those consequences will follow. The same protection extends to employees and independent contractors who exercise their CCPA rights.7California Legislative Information. California Civil Code 1798.125 – Consumers Right of No Retaliation Following Opt Out or Exercise of Other Rights
If a Business Ignores Your Request
Enforcement runs through the California Attorney General and the California Privacy Protection Agency. The Attorney General can bring a civil action for up to $2,500 per violation, or up to $7,500 per intentional violation or violation involving a minor’s personal information, with those figures adjusted annually for inflation.8California Legislative Information. California Civil Code 1798.199.90
One boundary to be aware of: the CCPA’s private right of action, which lets consumers sue directly for statutory damages, only applies when a business fails to keep reasonable security in place and your unencrypted personal information is exposed in a breach.9California Legislative Information. California Civil Code 1798.150 – Personal Information Security Breaches Ignoring a deletion request is not a data breach and does not open that door. Complaints about unhonored deletion requests go to the Attorney General or the California Privacy Protection Agency.
Related Tools: Global Privacy Control and the Delete Act
California requires covered businesses to honor the Global Privacy Control (GPC), a browser-level signal that tells every site you visit not to sell or share your personal information.10State of California – Department of Justice – Office of the Attorney General. Global Privacy Control (GPC) GPC is an opt-out, not a deletion request. It stops new data from being sold or shared, but existing data stays until you submit a deletion request through the channels above.
Starting August 1, 2026, the California Delete Act adds a separate mechanism aimed at the data broker industry. The California Privacy Protection Agency will operate a centralized system where a single request applies to every registered data broker at once, and brokers must check the system at least every 45 days and act on pending requests.11California Privacy Protection Agency. California Approves Delete Act Regulations It sits on top of your CCPA rights rather than replacing them.